HIGH 7.5 Go

Improper Authentication in HashiCorp Vault

GHSA-rq95-xf66-j689 · BIT-vault-2021-3282 · CVE-2021-3282 · GO-2024-2509

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

HashiCorp Vault Enterprise 1.6.0 & 1.6.1 allowed the remove-peer raft operator command to be executed against DR secondaries without authentication. Fixed in 1.6.2.

Ready to move

Start Securing

Free, no credit card | First findings in minutes